Post

2026-05

2026-05

This release tracker is LLM-curated and based on the official Microsoft product sources listed below. It provides an architect-grade summary of recent features, changes, and announcements. Always verify critical details against the official documentation. List of all raw markdown files for the releases are at https://github.com/pisinger/pisinger.github.io/tree/main/_ms_release_radar

Microsoft Security Release Radar - May 2026

πŸ“¦ Azure Container Apps

IndicatorFeatureTypeDescription
🟑Defender for Cloud support for Azure Container Apps (Serverless Containers Posture)PreviewBring Azure Container Apps environments into Defender for Cloud’s Serverless Containers Posture experience for unified posture management across the container estate.
🟒Confidential Compute support on Azure Container AppsGARun regulated or sensitive containerized workloads with stronger data-in-use protection via hardware-based isolation.
🟒Monitor HTTP traffic in Azure Container AppsGANew ContainerAppHTTPLogs diagnostic setting category exposes detailed HTTP access logs for high-volume request data.
🟒Additional OpenTelemetry destinations (New Relic, Dynatrace, Elastic)GAEnhanced OTel capabilities with expanded third-party observability platform endpoint options.
🟒Override Scale Rules in Azure Functions on Azure Container AppsGANew allowScalingRuleOverride property lets customers override platform-managed KEDA scale rules.
🟑Azure Container Apps SandboxesPreviewHyper-V isolated sandboxes for secure execution of untrusted code with pre-warmed pools and MCP integration.
🟑Azure Container Apps ExpressPreviewStreamlined container runtime without environment setup, featuring sub-second startup and scale-to-zero.
πŸ”΅Running production AI agents on Azure Container AppsNew/UpdatedFoundry Agent Service uses ACA as runtime for long-running, event-driven AI agents with serverless scaling and built-in security.
πŸ”΅Custom scaling control with KEDA rule overridesNew/UpdatedOverride platform-generated KEDA rules for full control over scaling thresholds, event sources, and multi-signal scenarios.
πŸ”΅Modernizing legacy applications to ACANew/UpdatedGitHub Copilot App Modernization reduces legacy-to-ACA migration effort from weeks to hours with managed identity and Key Vault integration.
πŸ”΅Safely executing AI-generated code with Dynamic SessionsNew/UpdatedHyper-V isolated sandboxes for AI-generated code execution with pre-warmed pools and MCP integration.

🧱 Azure Container Instances

No updates for May 2026.

β›΅ AKS

IndicatorFeatureTypeDescription
πŸ”΄AKS-2026-0004: Container Insights add-on nodes/proxy permission RCE riskSecurityContainer Insights add-on uses nodes/proxy permission on AKS < v1.33, enabling potential RCE via Kubelet API. Upgrade to v1.33+ for fix.
πŸ”΄AKS-2026-0003: CVE-2026-31431 β€œCopy Fail” LPE advisorySecurityLocal privilege escalation in Linux kernel algif_aead module (CVSS 7.8 HIGH). Requires code execution on the node.
πŸ”΄Kubernetes patch versions 1.35.4, 1.34.7, 1.33.11 with Go CVE fixesSecurityPatches address CVE-2026-27140, CVE-2026-27143, CVE-2026-27144, CVE-2026-32282, CVE-2026-32283, CVE-2026-32288, CVE-2026-32289.
πŸ”΄Kubernetes patch versions 1.35.5, 1.34.8, 1.33.12SecurityAdditional patch releases for Kubernetes versions.
πŸ”΄Azure Blob CSI driver security patch updatesSecurityAzure Blob CSI driver updated to v1.26.12 (AKS 1.32+) and v1.27.5 (AKS 1.34+).
πŸ”΄Azure Disk CSI driver upgradeSecurityUpgraded to v1.33.10 (AKS 1.33-1.34) and v1.34.4 (AKS 1.35).
πŸ”΄Azure File CSI driver upgradeSecurityUpgraded to v1.33.10, v1.34.6, v1.35.3 across AKS versions.
πŸ”΄Cloud Provider Azure v1.36.0 updateSecuritycloud-controller-manager and cloud-node-manager updated; health-probe-proxy updated to v1.36.1-1.
πŸ”΄Azure CNI Powered by Cilium updateSecurityCilium v1.19.3 (K8s 1.36+) and v1.18.9 (K8s 1.34) with security patches.
πŸ”΄ACNS DNS proxy security patch updatesSecurityDNS proxy updated to v1.18.9-260520 on AKS 1.34+ addressing CVEs.
πŸ”΄Azure Policy add-on v1.15.5-1 CVE patchesSecurityPatches CVE-2026-25679, CVE-2026-27142, CVE-2026-27139, CVE-2026-32280, CVE-2025-68121, CVE-2025-61726, CVE-2025-61728, CVE-2026-32281, CVE-2026-32283.
πŸ”΄Defender for Containers sensor v0.9.53 / v0.8.50SecuritySensor upgrades with malware scanning capability and drift detection blocking support.
πŸ”΄Defender for Containers sensor v0.10 on AKS 1.36SecurityNew sensor version available on AKS 1.36.
🟒Windows Server 2025 GA on AKSGAWindows Server 2025 node pools now generally available on K8s 1.32+ with CLI 2.87.0+.
🟒Azure Container Linux GA on AKSGAAzure Container Linux is now GA as an OS option on AKS starting v1.34.
🟒Azure Policy add-on VAP generationGAPolicy add-on now generates ValidatingAdmissionPolicies for CEL-based enforcement with fail-closed.
🟒AKS end of support notificationsGAAutomatic notifications when cluster K8s version approaches/passes end of support, via Azure Resource Graph.
🟑Azure Linux 3.0 confidential VM preview (Fairfax)PreviewConfidential VM support for Azure Linux 3.0 in US Gov regions.
🟑In-place node pool resizePreviewResize VMSS-based node pool VM size without manual migration.
🟑Automatic Pod Disruption Budget managementPreviewAKS extension auto-creates PDBs and scales up replicas to unblock node drain.
⚫Istio add-on asm-1-27 deprecatedDeprecationRevision asm-1-27 of Istio service mesh add-on deprecated; upgrade to 1.28+.
⚫Windows Server Annual Channel for Containers retiredDeprecationRetired May 15, 2026; migrate to LTSC by May 15, 2027.
⚫Windows Server 2019 retiredDeprecationRetired March 1, 2026; no new images or security patches. Remove by April 1, 2027.
⚫Flatcar Container Linux for AKS retiring June 8, 2026DeprecationNo new images or patches after June 8, 2026; migrate to Azure Container Linux.
🟒Managed system node pools GA for AKS AutomaticGANew AKS Automatic clusters preconfigure managed system node pools with enhanced security restrictions.
πŸ”΅LocalDNS auto-enabled on K8s 1.36+New/UpdatedLocalDNS automatically enabled on node pools running K8s 1.36+.
πŸ”΅Node Auto Provisioning LocalDNS defaultNew/UpdatedNAP Standard SKU on K8s 1.36+ defaults to LocalDNS mode Preferred.
πŸ”΅Application routing Gateway API access logsNew/UpdatedGateways using Gateway API now write access logs to stdout by default.
πŸ”΅Application routing DNS/TLS for Gateway APINew/UpdatedSupports TLS via Key Vault CSI driver and DNS A records via ExternalDNS CRDs.
πŸ”΅Migration to block/none outbound typesNew/UpdatedAKS now allows migration from managedNATGatewayV2 to block/none outbound types for network-isolated clusters.
πŸ”΅Pod CIDR overlap validationNew/UpdatedAKS validates pod CIDR ranges against reserved IP ranges (172.30.0.0/16, 172.31.0.0/16) during create/update.
πŸ”΅Calico/Azure NPM block on K8s < 1.30New/UpdatedInstall/uninstall operations rejected on clusters running K8s earlier than 1.30.
πŸ”΅AGIC add-on subnet restrictionNew/UpdatedAGIC blocked from using AKS-managed aks-appgateway subnet; use dedicated subnet instead.
πŸ”΅Istio v1beta1 Gateway fixNew/UpdatedFixed β€œUnknown gvk” error from admission webhook for v1beta1 Gateway resources.
πŸ”΅Multiple Standard Load Balancers orphaned nodes fixNew/UpdatedOrphaned nodes now included during rebalance and distributed evenly.
πŸ”΅Karpenter/KEDA silent install failure fixNew/UpdatedCluster create/update now fails with error on Karpenter/KEDA install failure.
πŸ”΅Azure Monitor Prometheus add-on v7.0.0New/UpdatedUpdated to May 2026 release.
πŸ”΅NAP Karpenter provider v1.12.1New/UpdatedUpdated Karpenter provider for Node Auto Provisioning.
πŸ”΅AKS Windows and Linux image updatesNew/UpdatedUpdated node images for Windows Server 2022/2025/23H2, Azure Linux v3.0, Ubuntu 22.04/24.04.

⚑ Azure Functions

IndicatorFeatureTypeDescription
⚫TLS 1.0 and TLS 1.1 retirement in App Service, Functions, Logic AppsDeprecationConnections using TLS 1.0/1.1 will be rejected after May 31, 2027. Migrate to TLS 1.2+.
🟑TLS/SSL certificate support for Flex ConsumptionPreviewSite-scoped certificate model with up to 3 private and 3 public certificates per function app, supporting Key Vault and managed certificates.
🟒Durable Task Scheduler Consumption SKUGAPay-per-use durable workflows with up to 500 actions/second, 30-day retention, and Entra ID RBAC.

πŸ“Š Azure Monitor

IndicatorFeatureTypeDescription
πŸ”΅Workspace replication private link supportNew/UpdatedWorkspace replication now supports private links during failover, removing previous BCDR limitation for private endpoint customers.

☁️ Microsoft Defender Cloud Apps

IndicatorFeatureTypeDescription
🟑Disable informational alerts for unsanctioned app accessPreviewNew toggle to suppress informational alerts for blocked unsanctioned app access while keeping blocking enforcement active.

🧠 Microsoft Copilot Studio

IndicatorFeatureTypeDescription
🟒Computer use for agentsGAAgents can now automate web and desktop apps by controlling browsers and desktop applications.
🟒Prompt node in agent flowsGASingle AI call with dynamic content and model selection for translation and data extraction.
🟒Microsoft 365 Copilot nodeGASend prompts to M365 Copilot or specific agents for research and audit drafting.
🟒Consent-based recording on voice agentsGAConfigurable compliance behavior and retention settings for call recording consent.
🟒Agent inventory schemaGADiscover and audit all Copilot Studio agents from admin center, API, or Azure Resource Graph.
🟑Agent readiness and issue statusPreviewConsolidated status page for publishing errors, runtime issues, and configuration blocks.
🟒Asynchronous responses for agent flowsGALong-running processes can exceed the two-minute limit and return results asynchronously.
🟑Microsoft Entra agent identitiesPreviewAuto-create Entra agent identities for scoped connector permissions, Conditional Access, and DLP.
🟑Computer use standalone toolsPreviewModular, reusable UI automation with built-in governance and observability.
🟑Mistral Medium 3.5 as primary AI modelPreviewExperimental option alongside Anthropic, xAI, and other providers.

πŸ”¬ Defender Container Sensor

IndicatorFeatureTypeDescription
🟒Sensor v0.10.5 β€” Runtime antimalware detection and blocking GAGAGeneral availability of runtime antimalware detection and blocking, Bottlerocket OS support, Nexus Baremetal compatibility, and Go dependency security upgrades.
🟒Sensor v0.9.58 β€” Bottlerocket OS support GAGABottlerocket OS support GA, Nexus Baremetal compatibility, and Go dependency security upgrades.
🟒Sensor v0.8.51 β€” Nexus Baremetal compatibilityGAImproved Nexus Baremetal cluster compatibility and Go dependency security upgrades.

🚨 Microsoft Security Exposure Management

IndicatorFeatureTypeDescription
πŸ”΅Senior Executive User Workstation classificationNew/UpdatedNew predefined Device classification rule for critical assets list, identifying devices used by senior executives.

πŸ›‘οΈ Microsoft Defender Cloud

IndicatorFeatureTypeDescription
🟑Private clusters protection for gated deployment, binary drift, malware detectionPreviewDefender sensor support extended to private clusters for container protection features.
🟑Malware detection for EKS and GKE nodesPreviewKubernetes node malware coverage expanded beyond AKS to EKS and GKE multicloud environments.
🟒On-demand malware scanning of Azure FilesGAMalware scanning for Azure Files now GA, supporting Azure portal, REST API, Logic Apps, Automation, and PowerShell.
🟒Defender for Open-Source Relational Databases on AWS RDSGABecomes GA June 1, 2026; billing begins for preview onboarded instances.
🟑Cloud security reporting in Microsoft Defender portalPreviewCreate, customize, and share security insights with built-in CNAPP Executive Summary and Cloud Posture reports.
🟑Scanning support for Docker Hardened container imagesPreviewPreview support for scanning Docker Hardened container images.
🟒Defender Experts for Servers as managed XDRGAManaged XDR option for on-premises and multicloud servers protected by Defender for Cloud.
🟑SQL Vulnerability Assessment Express Configuration for Azure SQL MI and SynapsePreviewExpress configuration for SQL VA on Azure SQL Managed Instance and Synapse.
🟒Updated Helm installation for Defender for Containers sensorGAUpdated Helm installation method for the Defender for Containers sensor.
🟒Individual recommendations GA; legacy grouped recommendations deprecatedGAIndividual recommendations now GA; legacy grouped recommendations deprecated.
🟒Daily score calculation enhancement for risk-based Cloud secure scoreGAEnhanced daily score calculation for risk-based cloud secure score.
🟒Defender for Cloud integration into Defender portalGADefender for Cloud now integrated into the Microsoft Defender portal.
🟒Defender for Cloud and GitHub Advanced Security integrationGAIntegration between Defender for Cloud and GitHub Advanced Security now GA.

πŸ›‘οΈ Microsoft Defender Unified SecOps

No updates for May 2026.

🎯 Microsoft Defender XDR

IndicatorFeatureTypeDescription
🟒Defender Experts for Servers as standalone offeringsGAManaged XDR and threat hunting for on-premises and multicloud servers, now available as standalone offerings.
🟑Automatic attack disruption β€” device isolationPreviewAutomatic isolation of compromised devices from the network during high-confidence incidents, blocking attacker communication while keeping security services connected.
πŸ”΅Advanced hunting Take action wizard for emailNew/UpdatedAllow or block top-level domains and file attachment hashes in emails based on advanced hunting query results.
πŸ”΅Hunting graph identity-focused scenariosNew/UpdatedNew predefined scenarios for Kerberoast, AS-REP roast, domain compromise, OAuth app risks, and guest user access.
🟑Defender Chat experiencePreviewOpen prompt chat assistant built into Defender for SOC analysts to investigate threats in plain language.

πŸ” Microsoft Defender Endpoint

IndicatorFeatureTypeDescription
🟒Defender endpoint security for Windows 7 SP1 and Windows Server 2008 R2 SP1GA[Windows] Advanced protection for legacy Windows 7 SP1 and Server 2008 R2 SP1 devices via Defender deployment tool.
🟑Enhanced exposure score in Defender Vulnerability ManagementPreviewNew exposure score model incorporating EPSS exploit prediction data and asset context (internet-facing status, criticality).
🟑Schedule antivirus scans on LinuxPreview[Linux] Configure scheduled quick and full scans via managed JSON, Defender portal, or mdatp CLI.
🟑Automatic device isolation (automatic attack disruption)PreviewAutomatic isolation of compromised devices blocking most network traffic while keeping security services connected.
🟒Custom data collectionGARule-based telemetry collection expansion beyond defaults; max event limit increased from 25,000 to 75,000 events per device per 24 hours.
🟒Configure offline security intelligence update settings for Linux from portalsGA[Linux] Configure offline security intelligence update settings from Defender and Intune portals.
🟑Selective Response ActionsPreviewTailor high-impact security operations on Tier-0 systems and high-value assets during onboarding.
🟒Windows Defender Antivirus Platform 4.18.26040.7 / Engine 1.1.26040.8GA[Windows] See enhancements and features for this release.

πŸ’Ώ MDE Detailed Releases

Windows

IndicatorFeatureTypeDescription
πŸ”΅Fixed remote-share file scans missing detections via symlinkNew/Updated[Windows] Fixed remote-share file scans missing detections when files were accessed through a symlink.
πŸ”΅Fixed mpcmdrun -scan non-ASCII character displayNew/Updated[Windows] Fixed mpcmdrun -scan output incorrectly displaying non-ASCII characters in localized paths and threat names.
πŸ”΅Fixed network protection watchdog timersNew/Updated[Windows] Fixed network protection watchdog timers silently not firing.

macOS

No updates for May 2026.

Linux

No updates for May 2026.

🏒 Microsoft Entra ID

IndicatorFeatureTypeDescription
🟑Soft-delete for Microsoft Entra Device objectsPreviewRecoverable device deletion with defined retention period, preserving device identity and security artifacts for Entra joined, registered, and hybrid joined devices.
πŸ”΅NetBiosName resolution test reclassified to informationalNew/UpdatedNetBIOS Name Sysvol Connectivity test in AD DS health monitoring agent changed from alerting to informational-only to reduce alert noise.
πŸ”΅Enhanced admin authorization for Entra Connect Sync changesNew/UpdatedInteractive admin sign-in required for sync configuration changes via wizard or PowerShell, strengthening authorization model.
πŸ”΅Workload identity-based authentication for SAP SuccessFactorsNew/UpdatedTransition from basic auth to Entra workload identity with short-lived tokens for SAP SuccessFactors provisioning, ahead of SAP’s November 2026 basic auth deprecation.
🟑Sensitivity labels for Microsoft Entra security groupsPreviewApply Purview sensitivity labels to Entra cloud security groups to govern guest access settings.
🟒Account Discovery for connected applicationsGAVisibility into all accounts (including orphan accounts) within connected applications via provisioning discovery reports.
🟒Cross tenant group synchronizationGASynchronize security groups across Entra tenants for centralized group management and cross-tenant collaboration.
πŸ”΅Modernized My Account pagesNew/UpdatedRedesigned Devices, Personal Info, and Organizations pages with improved BitLocker key visibility and organization leave functionality.
πŸ”΅Passkeys (FIDO2) support in registration campaignGARegistration campaigns now support passkeys as an authentication method, driving passkey adoption at scale.
πŸ”΅Automate user attribute updates in Lifecycle WorkflowsNew/UpdatedNew User Attribute Updates task for automated attribute value setting/clearing within lifecycle workflows.
πŸ”΅System-preferred authentication expanded to first-factorGASystem-preferred authentication now covers first-factor sign-in, enabling passwordless sign-in for users with phishing-resistant credentials.
πŸ”΅High Scale Compatibility mode for External IDGAEnables migration from Azure AD B2C to Entra External ID while preserving existing user directory for large-scale customer identity platforms.
πŸ”΅Expanded policy storage for passkeys (FIDO2)New/UpdatedDedicated 20-KB policy allocation for passkeys; max passkey profiles increased from 3 to 10.
πŸ”΅Azure Role assignments governed via Entitlement ManagementNew/UpdatedGovern Azure role assignments at MG/Sub/RG level through access packages with request, approval, and lifecycle governance.
πŸ”΅Manage Agent ID sponsorship lifecycle with Lifecycle WorkflowsGAAutomatic sponsorship transfer to manager when sponsor leaves; lifecycle workflows for agent identity sponsor notifications.

πŸ“Š Microsoft Fabric

IndicatorFeatureTypeDescription
🟑Eventstream Business Events publisherPreviewPublish governed, discoverable business signals from Eventstream canvas with filtering, aggregation, and thresholding.
🟑Service principal support for Fabric data agentsPreviewSPN authentication for Fabric data agents enabling application identity API calls instead of delegated user tokens.

πŸ—οΈ Microsoft Foundry

IndicatorFeatureTypeDescription
πŸ”΅Trace-based evaluation for external and hosted agentsNew/UpdatedGrade real production traces from Foundry, GCP, AWS, or any framework without hand-curated datasets.
πŸ”΅Grok 4.3 model availabilityNew/UpdatedxAI’s latest model available in Foundry for advanced agentic and domain-specific workloads.
πŸ”΅DeepSeek V4 model familyNew/UpdatedDeepSeek’s newest model family expands open-model choice in the catalog.
πŸ”΅GPT-5 Reinforcement Fine-Tuning (Gated GA)GARFT graduates to gated GA with enterprise-ready compliance and SLA coverage.
🟒Managed VNET GAGAMicrosoft-managed network isolation reaches general availability.
πŸ”΅Project-level cost attributionNew/UpdatedSee LLM costs by project for budget tracking and governance.
πŸ”΅Content Understanding improvements GAGARead and layout analyzers reach GA alongside Logic App connector and Foundry NextGen integration.
πŸ”΅Foundry Agent Service SDK 2.2.0New/UpdatedPreview skills and toolboxes; external agent definitions across Python, JS/TS, and .NET.

πŸ†” Microsoft Defender Identity

IndicatorFeatureTypeDescription
πŸ”΅Sensor v3.x supports all identity roles on domain controllersNew/UpdatedSensor v3.x now supports DCs running Entra Connect, AD FS, and AD CS identity roles.
πŸ”΅Increased sensor capacity (1,000 per workspace)New/UpdatedSensor limit increased from 350 to 1,000 per workspace.
πŸ”΅New security alerts for Entra IDNew/UpdatedEight new alerts: guest user promoted to member, user created as Global Admin, failed credential abuse, randomized user agent sign-in, stolen session cookie (detect + replay), Conditional Access bypass via non-compliant device, suspicious third-party MFA method addition.
πŸ”΅Known limitation: Windows Server 2025 sensor v2β†’v3 migration unsupportedNew/UpdatedMigration of DCs running Windows Server 2025 from sensor v2.x to v3.x not supported; continue using v2.x.

πŸ“± Microsoft Intune

IndicatorFeatureTypeDescription
πŸ”΅Multi Admin Approval enforces on API calls by automationNew/UpdatedMAA now applies to Microsoft Graph API calls from service principals and automation; missing approval headers return HTTP 403.
πŸ”΅Intune RBAC roles inherit Copilot accessNew/UpdatedIntune Administrator role gets Security Copilot owner access; all other Intune RBAC roles get contributor access automatically.
πŸ”΅Guidance for device-reported values in compliance reportsNew/UpdatedUpdated documentation clarifying device-reported values as informational with security considerations.
πŸ”΅Complete Platform SSO registration during macOS ADENew/Updated[macOS] Platform SSO during Automated Device Enrollment for immediate Entra ID resource access at desktop.
πŸ”΅Enhanced app inventory with faster data updatesNew/Updated[Windows] Faster, more detailed app inventory with richer metadata and device inclusion controls.

πŸ” Azure Logic Apps

IndicatorFeatureTypeDescription
⚫TLS 1.0 and TLS 1.1 retirementDeprecationConnections using TLS 1.0/1.1 will be rejected after May 31, 2027. Migrate to TLS 1.2+.

πŸ“§ Microsoft Defender Office 365

No updates for May 2026.

πŸ”Ž Microsoft Purview

IndicatorFeatureTypeDescription
🟒Data security and compliance protections for Microsoft Agent 365GAGA of data security and compliance protections for Microsoft Agent 365.
🟒Standalone data asset data quality scanGAGA of standalone data quality scanning for data assets.
🟒Incremental data quality scanGAGA of incremental data quality scanning.
🟒Configurable data quality thresholdsGAGA of configurable thresholds for data quality rules and assets.
πŸ”΅DLP admin permissions for unmanaged cloud apps in EdgeNew/UpdatedAdded Directory Reader, Edge, and Intune admin permissions required for DLP activation in Edge for Business.
πŸ”΅Edge browser profile scope clarification for cloud DLPNew/UpdatedPolicies for unmanaged apps apply across all Edge profiles; managed apps apply only in work profile.
πŸ”΅DeepL and Zapier removed from unmanaged AI apps listNew/UpdatedRemoved DeepL and Zapier from supported unmanaged AI apps for Edge browser DLP.
🟑Block access for specific external domains/users in DLPPreviewNew sub-option for SharePoint/OneDrive DLP to block sensitive file access for specific external domains or user SMTPs.
πŸ”΅OCR support in Data Security InvestigationsNew/UpdatedImage files automatically processed with OCR; extracted text merged and vectorized for AI analysis.
πŸ”΅Custom examinations in Data Security InvestigationsNew/UpdatedDefine custom examination focus with prompts beyond built-in examination areas.
πŸ”΅Large audit search result guidanceNew/UpdatedGuidance for working with audit searches exceeding ~3,000-item limit using Audit solution and time-based slices.
🟒Data Security Posture Management new version GAGANew DSPM version GA with guided workflows for proactive risk management; partner solutions and DSPM Agent remain in preview.
πŸ”΅Administrative unit support in DSPMNew/UpdatedSupport for administrative units in DSPM, bringing parity with classic versions.
πŸ”΅Inactive tenant data processing pauseNew/UpdatedProcessing paused for M365 data after 60 days of tenant inactivity; auto-resumes on return.
πŸ”΅Anthropic Claude (Enterprise) data connectorNew/UpdatedSupport for Anthropic Claude as AI application in activity explorer alongside Copilot, ChatGPT Enterprise, and others.
🟑Scanner cluster-level feature control via PowerShellPreviewEnable, disable, and configure cluster-level scanner features from PowerShell.
🟑Custom Reporting for scannerPreviewAdditional columns and tables in scanner database for custom Power BI or SQL-based reports.
🟑Custom posture reportsPreviewBuild tailored views of information protection and DLP activity with metric and chart cards.
🟑Manual labeling for MP4 filesPreviewRolling out manual sensitivity labeling support for MP4 files in SharePoint and OneDrive.
🟑Meeting label policy for artifactsPreviewAuto-apply meeting sensitivity label to recordings, transcripts, and notes.
🟑Label policy sync status visibilityPreviewSee sync status of sensitivity label publishing policies on Label policies page.
πŸ”΅Sensitivity label disable documentation updateNew/UpdatedUpdated documentation for disabling sensitivity labels for SharePoint and OneDrive after enablement.
πŸ”΅Auto-labeling policy-level activity monitoringNew/UpdatedPer-policy review pages for daily labeling activity, spot-checking, and failure investigation.

πŸ€– Microsoft Security Copilot

No updates for May 2026.

πŸ” Microsoft Sentinel

IndicatorFeatureTypeDescription
🟒Generate playbooks using AIGASOAR playbook generator creates Python-based automation workflows through conversational AI with Cline coding agent.
πŸ”΅UEBA enhancements: new settings, Okta V2, GCP anomaliesNew/UpdatedNew consolidated UEBA settings view; Okta V2 table support for anomaly detections; five new GCP Audit Logs anomaly detections for unusual login, privileged actions, resource deployments, secret/KMS access, and infrastructure patterns.

Top 5 Action Items

PriorityActionDueAffected Product(s)
πŸ”΄Upgrade AKS clusters to v1.33+ if Container Insights is enabled to eliminate nodes/proxy RCE riskImmediateAKS
πŸ”΄Apply AKS patch versions 1.35.5/1.34.8/1.33.12 to address Go CVEs (CVE-2026-27140 et al.)ImmediateAKS
πŸ”΄Migrate Windows Server Annual Channel node pools to LTSC before support removalMay 15, 2027AKS
πŸ”΄Migrate Flatcar Container Linux node pools to Azure Container LinuxJune 8, 2026AKS
πŸ”΄Plan TLS 1.0/1.1 migration to TLS 1.2+ for App Service, Functions, and Logic AppsMay 31, 2027Azure Functions, Logic Apps

Security Architect Observations

  • AKS nodes/proxy RCE (AKS-2026-0004) is the highest-severity item this month. The Container Insights add-on’s use of nodes/proxy on clusters < v1.33 creates a genuine RCE path via the Kubelet API. The fix requires a cluster upgrade to v1.33+ where fine-grained nodes/pods subresource authorization (KEP-2862) is available. For clusters that cannot upgrade immediately, restrict pod network access to port 10250 as defense-in-depth.
  • CVE-2026-31431 β€œCopy Fail” (CVSS 7.8) is a local privilege escalation in the Linux kernel’s algif_aead module affecting AKS nodes. While the attack vector requires local code execution, container breakout scenarios make this relevant. Ensure node images are patched via the May AKS release cycle.
  • Entra Connect Sync interactive admin authorization represents a meaningful security hardening for hybrid identity. Requiring interactive authentication for sync configuration changes closes a gap where stale or compromised credentials could modify sync settings. Plan for the operational impact on automation scripts and scheduled sync tasks.
  • TLS 1.0/1.1 deprecation across App Service, Functions, and Logic Apps (effective May 31, 2027) requires a systematic inventory of all clients and services connecting to these services. Use the Azure Retirement Workbook to identify affected resources and plan client-side TLS stack upgrades.
  • Defender for Containers sensor v0.10 on AKS 1.36 introduces GA runtime antimalware detection and blocking. This is a significant defense-in-depth addition for container workloads. Evaluate enabling malware scanning on production clusters, considering the performance and cost implications.

Security Operations Observations

  • Eight new Defender for Identity alerts focused on Entra ID provide critical coverage for identity-based attacks: session cookie theft/replay, Conditional Access bypass, guest account elevation, and suspicious MFA method additions. Review these alert rules and tune severity levels; consider creating automated response playbooks for the session cookie and Global Admin creation alerts.
  • Automatic attack disruption with device isolation (Defender XDR preview) changes the SOC workflow for high-confidence incidents. Devices will be automatically network-isolated while retaining connectivity to security services. Ensure your SOC has runbooks for reviewing and releasing automatic isolations, and test the feature in a controlled environment before broad enablement.
  • Sentinel UEBA GCP anomaly detections add five new detection types for GCP Audit Logs. If you monitor GCP environments, enable these detections and establish baselines for unusual login behavior, privileged actions, and resource deployment patterns to avoid false positive floods.
  • Defender for Cloud malware detection for EKS and GKE nodes (preview) extends container node malware coverage beyond AKS. Multi-cloud SOC teams should enable this preview and integrate alerts into their existing Kubernetes incident response workflows.
  • Purview DLP block for specific external domains/users (preview) on SharePoint and OneDrive gives SOC teams granular control over external data sharing. Review current external sharing policies and consider enabling this for high-risk domains or known bad actors.
  • Intune Multi Admin Approval enforcement on API calls will break automation scripts that modify protected Intune resources without the MAA approval workflow. Identify all service principals and automation using Graph API for Intune and update them to include approval headers or exclude them via the Exclusions tab.

References

ProductURL
Defender XDRhttps://learn.microsoft.com/en-us/defender-xdr/whats-new
Unified SecOpshttps://learn.microsoft.com/en-us/unified-secops/whats-new
Defender Endpointhttps://learn.microsoft.com/en-us/defender-endpoint/whats-new-in-microsoft-defender-endpoint
Defender Endpoint Releaseshttps://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint-releases
Defender Identityhttps://learn.microsoft.com/en-us/defender-for-identity/whats-new
Microsoft Sentinelhttps://learn.microsoft.com/en-us/azure/sentinel/whats-new
Microsoft Entra IDhttps://learn.microsoft.com/en-us/entra/fundamentals/whats-new
Microsoft Intunehttps://learn.microsoft.com/en-us/intune/whats-new/
Defender Cloud Appshttps://learn.microsoft.com/en-us/defender-cloud-apps/release-notes
Defender Office 365https://learn.microsoft.com/en-us/defender-office-365/defender-for-office-365-whats-new
Defender Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/release-notes
AKShttps://github.com/Azure/AKS/releases
Azure Container Appshttps://learn.microsoft.com/en-us/azure/container-apps/whats-new
Azure Container Instanceshttps://www.microsoft.com/releasecommunications/api/v2/azure?search=Azure%20Container%20Instances&$top=100
Azure Functionshttps://www.microsoft.com/releasecommunications/api/v2/azure?search=Azure%20Functions&$top=100
Azure Logic Appshttps://www.microsoft.com/releasecommunications/api/v2/azure?search=Logic%20Apps&$top=100
Azure Monitorhttps://learn.microsoft.com/en-us/azure/azure-monitor/fundamentals/whats-new
Defender Container Sensorhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-sensor-change-log
Security Copilothttps://learn.microsoft.com/en-us/copilot/security/whats-new-copilot-security
Defender Exposure Managementhttps://learn.microsoft.com/en-us/security-exposure-management/whats-new
Microsoft Purviewhttps://learn.microsoft.com/en-us/purview/whats-new
Microsoft Foundryhttps://devblogs.microsoft.com/foundry/category/whats-new/
Microsoft Copilot Studiohttps://learn.microsoft.com/en-us/microsoft-copilot-studio/whats-new
Microsoft Fabrichttps://learn.microsoft.com/en-us/fabric/fundamentals/whats-new
This post is licensed under CC BY 4.0 by the author.